The Weakest Link in Cybersecurity in 2023 – Dom Lombardi, Kandji
Dom Lombardi, vice president of security and trust at Kandji, explains why cyberattacks in 2023 will continue to exploit the weakest cybersecurity link of all: people
Transcript
This is Textron TV. Hey guys. Thanks for the throw.
We're here with Dominic Lombardi who's vice president of security and Trust for kanji, and we're going to be talking about what to expect from cyber attacks in 2023. Tom. Welcome the show.
Thank you for having me excited to be here. I guess we all think that there's gonna be more attacks than ever and that they're increasing in sophistication. But you know, what's your sense?
So we're gonna win more than we lose in 2023 or is this year shaping up to be maybe something? We don't want to remember. Well, I think if you look at some historical data, and I you make some predictive decisions based off of trends that we've seen over the past few years.
I think we'll see a lot more of this same Trends and attacks towards taking advantage of people. So that's where I think organizations really need to focus and Empower. If there were there people the members of their their staff to really be more security conscious and to make the right risk, baith diverse security investments into the system that will protect your people and you're more significant data.
Do we tend to obsess about the latest and greatest vulnerability when in fact, it seems like the Cyber criminals might be laughing at us because they're just focused on the basics and they're like, why am I going to so much trouble the steal your stuff when you make it easy for me by leaving your credentials exposed. Yeah, I think you know misconfigurations of public resources and some of the infrastructure that powers a lot of systems often, you know is taking advantage of by going through a traditional social engineering attack on the people, right? So thank you focusing on some of those attack vectors and looking at your threat landscape as an organization.
You can really apply the security controls to help mitigate against that initial sort of attack Factor. A lot of talk in the cyber security Community these days about all things chat GPT. Do you think the bad guys are gonna leverage that to start launching more sophisticated fishing attacks?
That humans might not detect. I'm sure but I'm sure are you know security practitioners they're looking at ways that they can leverage it as well. I know I know them I have explored different ways to do more quantitative risk analysis by using check EBT.
I know some of my peers of been exploring what we can do with it in order to also combat what other attackers are gonna you know use for Tool right often the you know, when we talk about the cat and about scan between hackers and you know threat actors and Security Professionals, we often look at and leverage the same tools to you know, turn around and now attack some of the system resources that we're using the trying to detect vulnerabilities and protect our system. So it's really interesting time. When you think about the current state of cybersecurity, is there something that is kind of a pet peeve of yours that you wish more organizations would just go address and it might make everybody's life simpler.
But for some reason just doesn't get the attention it deserves. Um, I think the biggest thing really is making sure that you have alignment if your organization around how you want to approach your thyroid risk and your organizations just posture thank you and goes back to what I mentioned earlier looking at the threat vectors that you have the risk, you know profile that your organization wants to know obtain or obtain or move towards. I think that's really what you you ought to consider really is I'm making sure that you're align there that way you can it prioritize from our space perspective going forward.
What do you think? The biggest challenge is when it comes to achieving that alignment? Because you know on the cybersecurity people talking in a language the business people understand and vice versa, or do we all need to sit down and come up with common terminology?
On the terminology is really important, right? Yeah, they using an analogy around flying you wouldn't get on an airplane. Yeah, the flight attendants the pit crew the air traffic controller and the pilot.
They're not speaking language and you need to know the same term then I think that's where cybersecurity professionals we need to do a better job at not only educating their business partners, but you know around cyber terms and the language that you know, the security practitioners speak, but really aligning to talking about cyber risk from a business perspective from a financial perspective. I think it's really important when you can talk about risk scenario and lots and areas for the business and translate. You know, what you potential path forward for mitigation are and allow Your Business Leaders to make the the decisions through or more risk conscious profile.
It seems like there's a lot of data privacy regulations coming down the pike new stuff from the SEC. Do you think all these regulations are going to force that conversation? I think so.
I think it helped provide additional context when you have to think about the regulatory landscape that you're working within as a company and as a business, but I think one of the biggest opportunities with some of the advancements and some you know more we call them Sovereign privacy laws is that they're raising the general population's Consciousness and I think that really allows businesses to approach. The relationships with their perspective customers and customers through that, you know that trust perspective where they were taking this privacy focused lens to how we're building our product. Because we care about privacy we care about your privacy.
We hear about the cybersecurity skills shortage all the time. Is there really a skill shortage or is it just not enough people that have the appropriate level of skills? Um, I think it's hard to Define what the appropriate level of skill I think often.
Cybersecurity was a an area where people you know have this perspective that you have to have a lot of skills in order to break in and I really want to debunk that because I think that there's a lot of opportunities and all different types of organizations to enter cyber security world. I think security practitioners need to think about how they can mentor people who are looking to enter the community and make the pathways more accessible and Equitable for people and to get back to the community by being involved in conversations like this and another sort of community-based organizations around different cyber Trends or privacy concerns. What's your sense of are we too dependent on internal teams to defend us and not enough on external service providers or is that the mix is currently correct and right but it seems to me a lot of organizations are.
Screaming about not having enough talent, but then they won't go hire some external help. Yeah, I think the skill shortages being addressed in a lot of different ways at different organizations. Some will focus on hiring Personnel to address different needs within the business other organizations may look to partner with Consultants or external parties to provide some of that sort of labor augmentation, but I think often what I'm seeing organizations start to do is to look at how they can leverage different technology that's coming out like you mentioned earlier with chat GPT and more ai-based Technologies the help sort of take that initial action for you and then allow practitioners to sort of respond to the event that the system is tuning for you that really important and Powerful think about how you can sort of address some of the business needs, you know to enhance security posture.
Well maintaining velocity for your organization without thoroughly hiring a lot of people or looking to external parties to help provide that from a Workforce perspective. All right, speaking of augmentation. What should the good guys expect from AI in 2023?
There's a lot of hype out there, but it's not clear what's working or what's kind of just that a dream state? Yeah, I think there's still a lot of dream states and a lot of and waving around what AI is capable of right now. And a lot of the different providers that are beginning to enter the space.
I think that's really, you know important context to look at is that a lot of these are new technologies that we're beginning to build right now. I do think that The tools that will differentiate themselves in 2023 goals that are going to enable practitioners to work efficiently through different other configurations and or responses to different events and to really take that data make it more accessible into other systems. They want to integrate with and to sort of do larger analysis around.
You know, I mentioned and thinking about the threat vectors and attack just before and taking a risk conscious profile to your security design you need data in order to do that and the data that you're getting from your different systems is really important to analyze and synthesize and I think that's really where people are going to be to make more investments in 23 and the tools that will differentiate themselves will have that capability. There's often a tendency to focus on the negative. But we talk a lot lately about shifting left and shifting.
Right and shifting left in my mind is the application development team is more involved shifting right is the it operations team is more involved with security operations. So are we making progress and turning this into more of a team sport? really think so I think you know at the teams that I've been a part of that are really successful and impactful are the ones that Ford strong relationships between all different parts of the business and just something really important ones there for your platform your product and for your, you know, your application and and the lifecycle by which you engage with support your customer needs, so And think we're seeing you really a kanji right now, but the teams that I'm managing and working with bear and some of my partners organizationally get to work with product and Engineering memes on building features within our product to help our customers achieve their goals.
So, you know, we Implement kanji products internally, we get to Leverage The technologies that we have and we get to that feedback into the product development life cycle. So when you talk about shifting a lot really fortunate to be able to do that in the product design phase all the way through like Early Access and implementation that we ultimately give back to our customers. So it's been really great being there and I think a lot of other teams are seeing that When you work with and partner your engineering and product teams, you can start to design security from the beginning which is often what we really want to be doing organizationally with with those business units that security practitioner is being a part of the design.
If you can incorporate your expertise security and privacy into the conversation and you can help, you know, your product and Engineering teams build things that will not only serve your customer need but while so protect their data and have their privacy in mind. What's your best advice to helping people achieve that goal do I just throw them all in the same room and lock the door until reason prevails because you know historically there's been a lot of demonization of groups, right the security people don't always trust the developers and developers think of security as kind of an obstacle. So how do we kind of get past all that?
Um, I think you it's growing people in a room and getting them together is an important first step. I think you that's when you start to build trust like you mentioned you actually get alignment on what the team to trying to do and I'm Never been a part of a successful security team that looks what roadblocks in because we block somebody from doing something. They tend to find a way around that and they make it a priority to say I want to continue to do something.
I'm gonna look to circumvent this block. So by partnering with teams getting alignment on your goals and making sure you have transparency about what you're it is you're doing and the different organizational risk your addressing you get better results as no an organization. No, I think security teams that I've been a part of and security teams that building are thinking through how can we achieve our business goals?
How can we help that organization reduce risk while we're doing that? All right, folks. Once again, we've established that Benjamin Franklin is the patron saint of cybersecurity because if we don't all hang together, we will surely hang separately Dom.
Thanks for being on the show. Really appreciate the time. Thank you again, and hope to be back sometime soon.
All right back to you guys in the studio.